IHS Configuration Authority Segmentation via Trusted Controller

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Information Handling Systems (IHS) face challenges in managing configurable settings remotely, leading to security vulnerabilities and unstable operations due to conflicting settings applied by multiple management tools, which traditional central authority management cannot adequately address.

Innovation Solution

The method involves factory provisioning of IHS to restrict configuration of individual settings to a single remote management tool, allowing updates to reassigned for exclusive management by a different tool, using a trusted controller to store credentials for authentication and validate communications from assigned configuration tools.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple remote management tools are allowed to configure IHS settings, then management flexibility and adaptability improve, but system stability deteriorates due to conflicting settings

Engineering Contradiction:
Improvemanagement flexibilityVSAvoidsystem stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the configuration management authority by dividing settings into different categories (firmware settings, operating system settings, application settings) and assigning each category to a specific management tool. This segmentation allows multiple tools to operate on different segments without conflict, maintaining both flexibility and stability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (the assignment data structure and validation logic) that mediates between multiple management tools and the IHS settings. This intermediary controls which tool can modify which setting, preventing direct conflicts while maintaining management flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If remote management of IHS settings is enabled, then ease of operation improves, but security vulnerabilities increase due to unauthorized access

Engineering Contradiction:
Improveremote management capabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-assigning specific settings to specific management tools during factory provisioning or initial setup. This pre-assignment creates a security framework before remote management operations begin, preventing unauthorized access while enabling legitimate remote management.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary validation mechanism that checks whether a management tool has authorization to modify a particular setting before allowing the modification. This intermediary security layer enables remote management while blocking unauthorized access attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If configuration permissions are assigned to multiple tools, then adaptability improves, but device complexity increases due to permission management

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidpermission management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal assignment data structure that can handle multiple management tools and multiple setting categories in a unified manner. This universal framework simplifies permission management by providing a single mechanism to control all configuration access, rather than requiring separate management for each tool-setting pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12073233B2Systems and methods for configuring settings of an IHS (information handling system)
Publication Date: 2024.08.27 DELL PROD LP
  • US12073233B2 patent drawing
  • US12073233B2 patent drawing
  • US12073233B2 patent drawing

AI summary

Systems and methods are provided that support configuration of settings of an Information Handling System (IHS), such as by external configuration tools that are delegated authority to configure any portion of the configurable settings of IHS. During factory provisioning of the IHS, an inventory of configurable settings of the IHS is generated and permissions are assigned for configuration of a portion of the configurable IHS settings by a configuration tool. During the factory provisioning, credentials are stored to the IHS for authenticating communications from the assigned configuration tool. Once the IHS has been delivered and deployed, configuration of the assigned portion of IHS is allowed when configuration requests from the assigned configuration tool are successfully validated against the credentials stored to the IHS during factory provisioning. The configurable settings of the IHS may include BIOS settings, operating system settings and settings supported by hardware components of the IHS.